Cybersecurity researchers have disclosed a new variant of the DarkSword iOS exploit kit designated P7 DarkSword. The variant reduces its on-device footprint while adding capabilities for stealing keychain and cryptocurrency wallet data directly from infected devices.

iVerify disclosed the findings in a report published Thursday. The researchers documented that P7 DarkSword establishes two-way command and control communication with attacker infrastructure, enabling remote command execution on compromised iOS devices.

The addition of keychain theft represents a direct threat to stored credentials and authentication tokens on iOS systems. Cryptocurrency wallet data theft exposes users to loss of digital assets. The two-way C2 communication capability allows attackers to issue commands to infected devices beyond the initial exploitation phase, enabling persistent control and data exfiltration.

The reduced on-device footprint suggests developers engineered P7 DarkSword to evade detection mechanisms that might flag larger malicious files or suspicious process behavior. A smaller footprint can help the exploit kit persist longer on devices before security tools identify its presence.

The DarkSword family has previously targeted iOS systems through exploit kits designed to bypass Apple's security protections. The addition of these new capabilities in the P7 variant indicates active development and refinement of the toolkit to increase its utility for attackers.

iVerify researchers did not disclose the specific attack vectors through which P7 DarkSword delivers its payload to iOS devices, nor did they provide details about the current scope of infections or affected iOS versions. The researchers also did not specify remediation steps beyond the general security practices users should follow to protect their devices.